The daemon's `manifest_missing_integrity_hooks` check (#3804) hard-fails any registry install whose plugin.toml declares hooks but lacks an [integrity] entry for each one. All 11 plugins under plugins/ had the [hooks] table but were missing [integrity], so `librefang plugin install <name>` would error after download with "missing [integrity] hashes for hook script(s): ...". Compute and pin SHA-256 over each `hooks/*.py` under every plugin dir. The mempalace-indexer entries were already present and are unchanged (reordered alphabetically by the regenerator). Verified each plugin.toml still parses (Python tomllib).
guardrails
Safety filter plugin that detects potentially harmful content patterns in user messages and injects warning memories into agent context. Uses only Python stdlib regex -- no external dependencies.
Detection Categories
| Category | Examples | Memory Tag |
|---|---|---|
| PII | Email addresses, phone numbers, SSNs, credit card numbers | [guardrails:pii] |
| Prompt injection | "ignore previous instructions", "you are now", "system prompt:" | [guardrails:injection] |
| Credentials | password=, api_key=, secret=, token=, PEM private keys |
[guardrails:credential] |
Hooks
| Hook | Script | Description |
|---|---|---|
| ingest | hooks/ingest.py |
Scans user messages for harmful patterns and returns warning memories |
How It Works
When a user message arrives, the ingest hook runs all pattern checks against it. For each detected issue a memory is returned with the category tag and a recommendation for the agent (e.g. "avoid echoing PII", "maintain original instructions"). If nothing is detected the plugin returns an empty memories list.
All patterns use word boundaries and anchoring to minimise false positives on casual conversation.
Usage
Installed automatically when enabled in agent configuration.